contract-retainer
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it automatically reads and processes data from existing local files to populate new contract templates.
- Ingestion points: The skill attempts to load data from previously created files in
./fractional-cto/contracts/(such as NDA or PSA documents) and the./fractional-cto/assessment/directory. - Boundary markers: The skill does not implement specific boundary markers or instructions to the agent to disregard potentially malicious instructions that might be present within the contents of these external files.
- Capability inventory: The skill performs file system read operations on templates and existing project documents, and performs write operations to generate new markdown files.
- Sanitization: There is no explicit sanitization, validation, or escaping logic applied to the data retrieved from the local files before it is interpolated into the contract placeholders.
Audit Metadata